Skip to content

Latest commit

 

History

History
54 lines (35 loc) · 2.11 KB

File metadata and controls

54 lines (35 loc) · 2.11 KB

FAIR Methodology Notice

About FAIR and FAIR-CAM

This software implements concepts from the Factor Analysis of Information Risk (FAIR) methodology and the FAIR Controls Analytics Model (FAIR-CAM), frameworks for cyber risk quantification and control effectiveness analysis.

Trademark and Affiliation

FAIR, FAIR-CAM, and the FAIR Institute logo are registered trademarks of the FAIR Institute.

This Software Is:

  • NOT affiliated with the FAIR Institute
  • NOT endorsed by the FAIR Institute
  • NOT certified by the FAIR Institute
  • An independent implementation created for research purposes

Official FAIR Resources

For official FAIR training, certification, and authoritative resources:

Implementation Notes

This implementation follows the FAIR-CAM specification as documented in:

  • "Measuring and Managing Information Risk: A FAIR Approach" by Jack Jones and Jack Freund
  • The FAIR-CAM technical standard published by the FAIR Institute

Any deviations from or extensions to the standard FAIR-CAM methodology are documented in the accompanying paper and in this repository.

Data Sources

This repository incorporates benchmark data from:

IRIS 2025 (Information Risk Insights Study)

Full Citation: Cyentia Institute. (2025). Information Risk Insights Study 2025: It's About Time. Sponsored by the Cybersecurity and Infrastructure Security Agency (CISA). Retrieved from https://www.cyentia.com/iris2025/

Users must comply with the respective licenses and terms of use for all data sources.

Questions

For questions about:

  • The FAIR/FAIR-CAM methodology itself: Contact the FAIR Institute
  • This specific implementation: Open an issue in this repository